Fun

News Feed - 2023-07-26 01:07:24

Tom Blackstone7 hours agoEra Lend on zkSync exploited for $3.4M in reentrancy attackThe lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.1128 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksLending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i— CertiK Alert (@CertiKAlert) July 25, 2023


According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.


Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.


On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM— Spreek (@spreekaway) July 25, 2023


Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.


Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.


In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”


To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.


Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Blockchain# Cryptocurrencies# Security# Ethereum# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to actually spend your Bitcoin, ExplainedTwitter vs. Threads: Users are the real losersZero-knowledge tech development heats up amid bear marketCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploitArbitrum-based Rodeo Finance exploited for second time, $1.5M stolen

News Feed

Ana Paula Pereira3 hours agoJPMorgan forecasts limited downside for crypto markets: ReportJPMorgan"s analysts consider Bitcoin"s declining open interest to be a sign that the current price trend may be weakening.1604 Tot
Baanx Acquires Stake in Major US Fintech Bank
Baanx Acquires Stake in Major US Fintech Bank press release PRESS RELEASE. Baanx, the fast growing B2B2C “Better than a Banking Platform” specializing in fintech servi
Ether price may dip after ETF 'novelty' wears off due to surging supply
Ciaran Lyons3 hours agoEther price may dip after ETF "novelty" wears off due to surging supplyInto The Cryptoverse founder Benjamin Cowen says if supply keeps increasing it will "revert" to similar levels befor
China’s Central Bank Digital Currency Now Has 261 Million Users — $14 Billion in Digital Yuan Transactions Made
China"s Central Bank Digital Currency Now Has 261 Million Users — $14 Billion in Digital Yuan Transactions Made China’s central bank digital currency now has 261 million u
Animoca Brands leads $7M funding round for Param Labs
Zoltan Vardai9 hours agoAnimoca Brands leads $7M funding round for Param LabsThe lack of Web3 gaming infrastructure remains the biggest hurdle for mainstream adoption, according to Param Labs’ CEO.3071 Total views1 Tot
New York Governor Signs Law Partially Banning Bitcoin Mining on Fossil Fuels
New York Governor Signs Law Partially Banning Bitcoin Mining on Fossil Fuels A moratorium on some crypto mining operations relying on carbon-based energy has been signed into law i
Martin Young2 hours agoCrypto Twitter will see less exposure on Google due to rate limit slashAnother impact of Elon Musk’s Twitter limits is lower search visibility on Google, according to SEO experts.1210 Total views
Price analysis 6/21: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, SHIB, AVAX
Rakesh Upadhyay6 hours agoPrice analysis 6/21: BTC, ETH, BNB, SOL, XRP, DOGE, TON, ADA, SHIB, AVAXBitcoin has broken below the immediate support of $64,602, increasing the risk of a fall to the crucial $60,000 price leve
Ezra Reguerra11 hours agoSWIFT says blockchain integration ‘more plausible’ than unifying CBDCsSWIFT claims that interlinking existing systems with blockchains is better for the short term than bringing CBDCs togethe
Bitcoin ETF activity to remain robust until the halving: Santiment
Martin Young3 hours agoBitcoin ETF activity to remain robust until the halving: SantimentIt is a “likely foregone conclusion” that high Bitcoin ETF activity will continue leading up to the halving, said Santiment.179
New Research Suggests Satoshi Nakamoto Lived in London Creating Bitcoin
New Research Suggests Satoshi Nakamoto Lived in London Creating Bitcoin The hunt for the mysterious Bitcoin inventor, Satoshi Nakamoto continues to this day, as
Russia’s Sberbank Denies Involvement in Recently Launched ‘Sbercoin’
Russia’s Sberbank Denies Involvement in Recently Launched ‘Sbercoin’ Sberbank, the largest bank in the Russian Federation, has denied connection to a new cryptocurrency calle